Compliance
NEWS ROUNDUP – 29th October 2025
Qilin ransomware tactics evolve, commercial spyware resurfaces, and municipal services face fresh extortion pressure. A Lanscope zero-day and BIND 9 risks demand swift patching, while Singapore tackles SIM-fraud networks on the ground. New supply-chain ransomware guidance and crypto-finance sanctions signal policy tightening. Plus, standards shifts in ICMPv6 and hashing preview changes coming to defensive stacks.
NEWS ROUNDUP – 27th October 2025
Qilin ransomware tactics evolve, commercial spyware resurfaces, and municipal services face fresh extortion pressure. A Lanscope zero-day and BIND 9 risks demand swift patching, while Singapore tackles SIM-fraud networks on the ground. New supply-chain ransomware guidance and crypto-finance sanctions signal policy tightening. Plus, standards shifts in ICMPv6 and hashing preview changes coming to defensive stacks.
NEWS ROUNDUP – 15th October 2025
Microsoft’s October Patch Tuesday, new CISA KEVs, and Oracle’s emergency ERP fixes headline a high-intensity 48-hour cycle. Law enforcement advanced with major crypto-fraud indictments and the UK ICO’s £14 million Capita fine. Global advisories from the NCSC and ISO refreshed defence and privacy standards, underscoring the convergence of regulatory accountability, ERP exploitation risk, and industrial system resilience.
NEWS ROUNDUP – 29th September 2025
Over the past 48 hours, DFIR teams faced active Cisco zero-day exploitation, evolving macOS XCSSET tactics, and BRICKSTORM espionage. Aviation operations suffered vendor software disruption; Harrods reported a third-party breach. INTERPOL announced 260 arrests targeting sextortion scams, and the NCA detained a UK suspect. CISA issued an emergency directive; NIST published compliance updates. Organisations should prioritise patching and secure-boot verification.
NEWS ROUNDUP – 19th September 2025
Across the past 48 hours, DFIR teams tackled Uvalde CISD’s ransomware fallout and major healthcare disclosures, while Google patched an actively exploited Chrome zero-day. Law enforcement advanced cases tied to the TfL intrusion and broader critical-infrastructure attacks. Policy and standards moved too, with the UK’s Cyber Growth Action Plan and new NIST guidance on KEMs and TLS 1.3 visibility initiatives.
